CVE-2015-3880
Summary
| CVE | CVE-2015-3880 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-19 15:29:00 UTC |
| Updated | 2017-09-27 17:42:00 UTC |
| Description | Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecified vectors. |
Risk And Classification
Problem Types: CWE-601
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phpbb | Phpbb | 3.1.0 | All | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | a1 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | a2 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | a3 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | b1 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | b2 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | b3 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | b4 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc1 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc2 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc3 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc4 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc5 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc6 | All | All |
| Application | Phpbb | Phpbb | 3.1.1 | All | All | All |
| Application | Phpbb | Phpbb | 3.1.2 | All | All | All |
| Application | Phpbb | Phpbb | 3.1.2 | rc1 | All | All |
| Application | Phpbb | Phpbb | 3.1.3 | All | All | All |
| Application | Phpbb | Phpbb | 3.1.3 | rc1 | All | All |
| Application | Phpbb | Phpbb | 3.1.3 | rc2 | All | All |
| Application | Phpbb | Phpbb | 3.1.4 | rc1 | All | All |
| Application | Phpbb | Phpbb | 3.1.4 | rc2 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | All | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | a1 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | a2 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | a3 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | b1 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | b2 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | b3 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | b4 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc1 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc2 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc3 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc4 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc5 | All | All |
| Application | Phpbb | Phpbb | 3.1.0 | rc6 | All | All |
| Application | Phpbb | Phpbb | 3.1.1 | All | All | All |
| Application | Phpbb | Phpbb | 3.1.2 | All | All | All |
| Application | Phpbb | Phpbb | 3.1.2 | rc1 | All | All |
| Application | Phpbb | Phpbb | 3.1.3 | All | All | All |
| Application | Phpbb | Phpbb | 3.1.3 | rc1 | All | All |
| Application | Phpbb | Phpbb | 3.1.3 | rc2 | All | All |
| Application | Phpbb | Phpbb | 3.1.4 | rc1 | All | All |
| Application | Phpbb | Phpbb | 3.1.4 | rc2 | All | All |
| Application | Phpbb | Phpbb | All | rc1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release Highlights/3.0.14 - phpBB Development Wiki | CONFIRM | wiki.phpbb.com | Third Party Advisory |
| Release Highlights/3.1.4 - phpBB Development Wiki | CONFIRM | wiki.phpbb.com | Third Party Advisory |
| phpBB 'functions.php' Open Redirection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Merge remote-tracking branch 'phpbb-security/ticket/security-180' int… · phpbb/phpbb@1a33506 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| phpBB • phpBB 3.0.14 and 3.1.4 Release - Please Update | CONFIRM | www.phpbb.com | Vendor Advisory |
| oss-security - Re: CVE Request: phpbb open redirect | MLIST | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.